The house

Privacy Policy

Effective 21 September 2026 · Version 10

This Privacy Policy describes how Drip Drops (“Drip Drops,” “we,” “our,” or “us”) collects, uses, and discloses information about you. It applies to information collected when you access or use our products or services (the “Services”) through our website at dripdrops.co and our iOS and Android apps (together, the “Site”).

Please read it carefully, so that you understand our practices. If you do not agree with them, your choice is not to use the Site or the Services. We encourage you to check back, so that you stay informed about our practices and the choices available to you.

01

What we collect

We collect information about you in three ways:

The categories we collect are:

So that the last category is not misread: because Stripe collects it on our behalf, we count it as information we collect, and we have listed it here rather than leave it unsaid. But it is entered directly into Stripe’s pages, and none of it - no identification document, no social security number, no bank account number - is transmitted to or stored on Drip Drops servers. What comes back to us is Stripe’s account identifier for you, and whether Stripe has cleared that account to receive money. The same division applies to full card numbers. Section 4 sets out both.

02

How we use it

We do not sell your personal information. The website shares limited information about your visit with TikTok and Meta to measure and target our advertising, which some privacy laws count as sharing for cross-context behavioural advertising; section 5 says exactly what is shared and section 6 how to opt out. The app shares the events section 5 lists with TikTok and Meta in the same way, and nothing else.

03

Who we share it with

The Services may contain links to third-party sites and services. Those links are for your convenience and do not imply endorsement, and we are not responsible for those parties’ practices. Anything you give a third party on its own site is covered by that party’s privacy practices, not by this policy.

04

Payments, payouts and shipping

These are the providers that receive your information, and what each one gets:

05

Cookies and similar technologies

The website at dripdrops.co keeps one item of its own in your browser’s local storage, named dd_visitor: a random identifier that lets our servers tell a new visitor from a returning one. With it we record the site usage described in section 1 - pages, sections, buttons, referrer and campaign tags - on our own servers and nowhere else. It is not a cookie, it is not read by anyone but us, and clearing the site’s data in your browser removes it. The opt-out switch below, Global Privacy Control and Do Not Track do not affect it, because nothing about it is shared or sold.

The website also loads two advertising trackers, the TikTok Pixel and the Meta Pixel. The pixels themselves receive neither your email address nor anything else you type, and learn nothing about an account, an order or a balance; what our own servers send Meta separately is set out below.

The TikTok Pixel tells TikTok which pages of the Site you view, which buttons you press and whether you join the waiting list, together with your IP address, your browser and device details, the page you arrived from and the time. It sets two cookies of TikTok’s, named _ttp and _tt_enable_cookie, so that TikTok can recognise the same browser again; if you are signed in to TikTok, TikTok may connect the visit to your TikTok account. We use it to measure whether our advertising on TikTok works and to show that advertising to people like the ones who visit.

The Meta Pixel tells Meta which pages of the Site you view and whether you join the waiting list, together with your IP address and browser details. It sets two cookies of Meta’s, named _fbp, which identifies your browser to Meta, and _fbc, which is set only when you arrive from a Meta advertisement and records which advertisement you clicked; if you are signed in to Facebook or Instagram, Meta may connect the visit to your account. Every report is sent with Meta’s Limited Data Use flag, which restricts how Meta may use it where state privacy law applies. We use it to measure whether our advertising on Meta’s platforms works and to improve how it is shown.

The iOS app carries TikTok’s and Meta’s measurement software for the same purpose. Each is told that the app was installed and opened, that a phone number was verified for a new account, that a box’s page was viewed and which box, that the add-money screen was opened, and that money was added to a balance, with the amount. With each of those it sends your device model, operating system version and IP address, an identifier the software makes up for the app, and your device’s advertising identifier only if you allow tracking when iOS asks, which it does once, after you accept the Terms. Neither piece of software receives your name, email address or phone number, the account identifier, which boxes you open, what you are credited or what you ship. The Android app carries neither piece of software, reads no advertising identifier, and reports nothing to either platform.

Our servers also send Meta their own copy of three of these events, so that Meta counts each once whether or not the browser’s or the app’s report reached it: joining the waiting list on the website, verifying a phone number for a new account, and adding money to a balance, with the amount. Each copy carries your IP address and browser or device details, and a hashed form of your email address; the two app events also carry a hashed form of the phone number on the account and of the account identifier. A hash is a one-way scrambling: Meta can match it against details it already holds, but cannot read the address or number back out of it. The website’s copy is sent only when the Meta Pixel was allowed to load in your browser, so the opt-outs below stop it too. The iOS app’s copies carry the advertising identifier and the hashed details only if you allow tracking when iOS asks; our servers send no copy of anything done in the Android app. Every report to Meta, whether from the website, the app or our servers, carries Meta’s Limited Data Use flag. TikTok’s own use of what it collects, on the website and in the app, is governed by TikTok’s privacy policy, and Meta’s by Meta’s privacy policy.

The only other third-party request the Site makes is for the web fonts it uses to render the page, which are served by Google Fonts and which therefore see your IP address.

The apps do not use cookies. Each stores a session credential on your device so that you stay signed in; we hold only a hashed form of that credential, never the credential itself. Signing out, or deleting your account, ends every session immediately.

To opt out of both pixels on the website, turn on Global Privacy Control or Do Not Track in your browser or in a privacy extension: when the Site sees either signal it loads neither pixel, and our servers send Meta nothing about your visit. Or use this switch, which stores the choice in this browser only and also removes the cookies named above:

Your browser has JavaScript switched off, so neither pixel can load in any case.

Blocking third-party requests works too. The Site works without the pixels, and without the web fonts, though without the fonts it will look plainer. In the iOS app, decline when iOS asks, or turn tracking off later under Settings, Privacy & Security, Tracking; the app then reports without the advertising identifier, and our servers’ copies of its events go without the hashed details.

06

Your choices and rights

Depending on where you live, you may also have the right to confirm whether we hold personal information about you, to access it, to correct it, to have it deleted, to receive a portable copy, to withdraw consent you have given (without affecting processing carried out before you withdrew it), and not to be discriminated against for exercising any of these rights. To exercise them, contact us using section 12. We may need to verify your identity before we act, and we may decline a request where we cannot verify it, or where the law requires us to keep the information.

The identity and bank details Stripe collects under section 4 sit in Stripe’s systems rather than ours, and are governed by Stripe’s privacy policy as well as this one. We will pass a request on where we can, but for that information Stripe may need to deal with you directly.

07

How long we keep it

We keep your information for as long as we need it to provide the Services, meet our legal and accounting obligations, enforce our agreements, and resolve disputes. Retention is judged category by category, according to why the information was collected and what law requires of us.

Deleting your account closes it, ends every active session at once, and stops any further use of your information to provide the Services. It is not an instant erasure of everything, for two reasons we would rather state plainly than bury:

Where you have a right to erasure and none of the grounds above apply, write to us and we will delete.

08

Where it is processed

Drip Drops is operated from the United States, and your information is stored and processed there. Our service providers may process it in other countries. If you use the Services from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection law may differ from the law where you live. Where the law requires safeguards for such transfers, we rely on our providers’ standard contractual clauses and equivalent measures.

09

How we protect it

We use reasonable procedural, physical and electronic safeguards, including encryption in transit and at rest, designed to protect your information against accidental or unlawful destruction, loss, misuse, alteration, and unauthorised access or disclosure. Session credentials are stored only as hashes. Card numbers and identity documents are held by our processors, not by us.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. The safety of your account also depends on you: use a device passcode, keep your sign-in provider secure, and tell us at once if you believe someone else has reached your account.

10

Age restrictions

The Site and the Services are for people aged 18 and over. We ask you to confirm your age, and we record that confirmation. We do not knowingly collect or solicit information from anyone under 18. If we learn or suspect that a user is under 18, we will close the account and delete the information as soon as we can. If you believe a child has given us information, contact us and we will delete it.

11

Changes to this policy

We change the Services regularly, and those changes sometimes mean we collect new information, or use what we already hold in a new way. When we revise this policy we will update the effective date and version at the top of this page. For material changes we will also tell you in the app or by email before they take effect. Your continued use of the Services after a change takes effect is subject to the updated policy.

12

Contacting us

Questions about this policy, and requests about your own information, go to our support page, or to the address below.

Operated by
Curated Drops, LLC
Address
800 Third Avenue FRNT A #1084
New York, NY 10022
United States
Email
support@dripdrops.co
← Back to Drip Drops